All insights
Compliance

How does the EU AI Act affect recruitment software?

Tools that screen, rank or match candidates are high-risk under the EU AI Act. Deployer duties apply from 2 August 2026: oversight, logs, candidate notice.

RE
Recruitifly Editorial
Editorial
2026-06-12·6 min read
On this page

The EU AI Act classifies recruitment software that screens, ranks, scores or matches candidates as high-risk, which makes it legal to use but regulated. From 2 August 2026, anyone using such a tool for hiring in the EU must provide trained human oversight, monitor the system, keep its logs and tell candidates that AI is involved. A few practices are banned outright already, including emotion recognition in interviews. The duties fall on you as the deployer, not only on your software vendor.

Why is recruitment software high-risk under the AI Act?

Annex III of the Act names employment as a high-risk area: systems used for the recruitment or selection of people, including placing targeted job advertisements, analysing and filtering applications, and evaluating candidates. In plain terms, if a feature screens CVs, ranks a shortlist, scores candidates against a job, or matches people to vacancies, it is high-risk. The label says nothing about how good the software is; it reflects the stakes, because a hiring decision shapes someone’s livelihood.

High-risk does not mean forbidden. It means your vendor, the provider in the Act’s language, owes product duties such as risk management, bias controls and technical documentation, while the employer or agency using the tool, the deployer, owes the operational duties below. To understand what the scores themselves do before you regulate them, read candidate scoring in an ATS explained.

Not every ATS feature qualifies, and a few are banned outright:

What the feature does Status under the AI Act
Emotion recognition in interviews or at work Banned since 2 February 2025
Inferring race, religion, sexuality or union membership from biometrics Banned since 2 February 2025
Social scoring of candidates Banned since 2 February 2025
Screening, ranking, scoring, matching, targeted job ads High-risk: allowed, full duties from 2 August 2026
Storing records, scheduling interviews, sending email Outside the high-risk rules

What is banned outright in hiring?

Three practices relevant to recruitment have been prohibited since 2 February 2025, with no grace period for tools already in use:

  • Emotion recognition at work, including AI that reads facial expressions or tone of voice in a video interview to infer how a candidate feels. Narrow medical and safety exceptions exist; assessing candidates is not one of them.
  • Biometric categorisation that infers protected traits, such as deducing ethnicity, religious belief, political opinion or sexual orientation from someone’s face or voice.
  • Social scoring, judging people on unrelated social behaviour or personal characteristics.

Top-end fines reach EUR 35 million or 7 percent of worldwide turnover, whichever is higher. If a tool in your stack does any of the above, the fix is not paperwork. It is turning the feature off.

Which deadlines matter, and who is covered?

The Act phases in:

  • 2 February 2025: the bans apply, plus a duty to make sure staff working with AI have adequate AI literacy.
  • 2 August 2025: governance rules, penalties and obligations for general-purpose models.
  • 2 August 2026: the date that matters for recruiters. The full high-risk obligations apply to hiring tools.
  • 2 August 2027: rules for AI embedded in separately regulated products.

The reach is extraterritorial. The Act covers deployers established in the EU, providers selling into the EU from anywhere, and organisations outside the EU whenever the system’s output is used in the EU. A US agency screening applicants for roles in Amsterdam is covered. So is a UK employer ranking candidates for its Dublin office.

What do recruiters have to do as deployers?

The Act splits responsibility. Your vendor must build the system to standard: risk management, representative training data, accuracy, documentation, conformity assessment and registration in the EU database. You must run it responsibly, which comes down to six duties:

  1. Follow the instructions for use. Vendors must supply them, and using a tool outside them shifts liability toward you.
  2. Assign human oversight to named people with the training, competence and authority to interpret outputs and overrule them.
  3. Monitor the system in operation, and suspend it and inform the vendor if it appears to present a risk.
  4. Keep the logs the system generates, for at least six months, where they are under your control.
  5. Tell people. Candidates must know they are subject to a high-risk AI system, and workers and their representatives must be informed before one is used on employees.
  6. Be ready to explain. A rejected candidate has the right to a clear, meaningful explanation of the role the AI played in the decision.

Little of this is alien. GDPR already restricts fully automated decisions and usually demands a data protection impact assessment for the same tool, so handle the two regimes together; our guide to a GDPR-compliant ATS covers that side.

What should you ask your ATS vendor?

Six questions, answers in writing, well before August 2026:

  1. Which of your features are high-risk under the Act, and which are not?
  2. Can we see the instructions for use and a summary of the technical documentation?
  3. How is bias tested, on what data, and how often are the results reviewed?
  4. Can the system explain an individual score in language a candidate would understand?
  5. What is logged, how long is it kept, and can we export it?
  6. Where is candidate data processed and stored? EU data residency matters for the GDPR half of the picture.

These questions apply to every vendor, whether you evaluate Greenhouse, Workable, Bullhorn, Teamtailor or Recruitifly; the differences show up in the answers. A vendor that cannot answer question 4 leaves you unable to honour a candidate’s explanation request, and that becomes your problem, not theirs.

How do human-approval workflows fit the oversight duty?

Oversight means a competent human who can interpret the output, decide not to use it, and override it. Clicking approve on everything does not count; the Act explicitly tells deployers to guard against that automation bias.

A propose-and-confirm workflow is the practical shape of this: the system drafts or suggests, a named recruiter approves or rejects each step, and the decision is recorded. Recruitifly’s assistant Fly works this way across every screen: it proposes a shortlist, a stage move or an outreach draft, and nothing happens until a recruiter confirms it. Scores carry visible reasoning rather than silent auto-rejection, which is the raw material for both oversight and explanations. Teams that want the records ready-made can add Recruitifly’s Compliance Engine, whose EUR 49 per month regional bundle includes EU AI Act impact records alongside GDPR core checks and country packs.

Whatever software you choose, apply one test: for any individual rejection, could you show which human approved it, on what information, and when? If the answer is yes, most of the deployer duties are already met. Recruitifly is in private beta at the moment; if you want to walk your current screening workflow through these duties, talk to us and we will map it with you.

Frequently asked questions

Is my ATS high-risk under the EU AI Act?

If it only stores candidate records, schedules interviews and sends email, no. The moment it screens applications, ranks or scores candidates, matches people to jobs, or targets job advertising, it falls under Annex III of the Act and is high-risk. Ask your vendor for a written list of which features qualify; you need it to know which duties apply to you.

When does the EU AI Act apply to hiring?

The bans, including emotion recognition in interviews, have applied since 2 February 2025, together with an AI literacy duty for staff. The full high-risk obligations for recruitment tools, covering oversight, logging and candidate notification, apply from 2 August 2026. The Act also reaches non-EU companies whenever the system's output is used for hiring in the EU.

Is automated CV screening banned in the EU?

No. Screening and ranking software is classified as high-risk, which means it stays legal provided the vendor meets product requirements and you provide human oversight, keep logs and tell candidates AI is involved. What is banned is different: emotion recognition in interviews, inferring protected traits from biometric data, and social scoring. GDPR separately restricts fully automated rejections without human involvement.

What do recruiters need to document under the AI Act?

Keep the logs your system generates automatically for at least six months, a record of who provides human oversight and how they were trained, evidence that candidates were informed AI was used, the vendor's instructions for use, and any data protection impact assessment. If a rejected candidate asks, you must also be able to explain the role the system played in the decision.

What are the penalties for breaking the EU AI Act?

Using a banned practice, such as emotion recognition in interviews, carries fines up to EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher. Breaching the high-risk obligations, including the deployer duties recruiters carry, goes up to EUR 15 million or 3 percent. National authorities can also order a system withdrawn from use.

RE

Recruitifly Editorial

Editorial

Related reading

Want to see how this looks on your own data?

No hard promises. Just a straight conversation about exports, stages, and your current stack.

Contact us